[SIGNALS WEEKLY] Shifting Access Paths: OT, Identity, and Adversarial AI

Some of this week’s most useful threat signals point to access paths that sit just outside the normal inventory: a cellular modem added by an OT integrator, a hotel captive portal steering a traveler toward token theft, or a passkey implementation that trusts the wrong lifecycle step.

Share
[SIGNALS WEEKLY] Shifting Access Paths: OT, Identity, and Adversarial AI
The perimeter is fine. Nobody asked the modem under the cabinet.

TL;DR

  • [Critical Infrastructure/OT] Internet-exposed PLCs—often via undocumented cellular modems and integrator remote access—are driving real-world water-utility lockouts, manual operations, and safety impacts, highlighting systemic OT discovery and access-control gaps.
  • [Espionage/Identity] State actors and criminals are converging on identity seams—captive-portal traffic manipulation, OAuth/device-code abuse, and emerging passkey implementation flaws—to achieve durable, passwordless account takeover against high-value travelers and admins.
  • [Threat Tradecraft/AI] Adversaries now use AI as an operational “co-pilot” (tooling development, phishing workflow automation, evasion of safety controls), signaling that detection must pivot from prompt content alone to surrounding infrastructure, behavior, and abuse patterns.

AlphaHunt

Stop doomscrolling, start decisioning. We chewed through the muck so your team doesn’t have to. → Subscribe!

Like this? Forward this to a friend!

(Have feedback? Did something resonate with you? Did something annoy you? Just hit reply! :))


Current Stories

TL;DR

  • [Critical Infrastructure/OT] CISA warned of a significant increase in threats targeting internet-exposed PLCs in the U.S. water sector; observed impacts include lockouts (password changes), PLC disconnects (IP changes), boil-water notices, and sustained manual operations.
    • Key exposure driver: undocumented cellular modems and remote access paths installed by vendors/integrators.
  • [Espionage/Identity] Microsoft attributed “CaptiveCrunch” to Storm-2945 (assessed sub-cluster of Midnight Blizzard/SVR): hospitality captive portals used for DNS/HTTP manipulation to steer travelers into credential/token theft.
    • Concrete detail: lures include device-code/OAuth phishing and “fake update / ClickFix” prompts; malware described includes Go-based Windows RATs and in-memory PowerShell infostealers targeting M365 tokens, browser cookies, and Wi‑Fi credentials.
  • [Vulnerabilities/KEV] CISA added CVE-2026-18577 (N-able N-central authentication bypass via alternate path/channel) to the KEV Catalog, reinforcing active exploitation risk and prioritization for patching/mitigation on exposed assets.
  • [Supply Chain/Policy] CISA + NSA + FBI + partners published updated “2026 Minimum Elements for an SBOM,” replacing the 2021 NTIA baseline and explicitly calling out modern software types (including AI and SaaS) where additional elements may be required.
  • [AI/Threat Enablement] Cisco Talos reported increasing adversary use of AI based on recovered prompt-log artifacts, showing AI is being used as a practical “ops assistant,” not just novelty.
    • Concrete detail: examples include AI-assisted development of DDoS tooling tied to a claimed bot pool of ~2,000 Android TVs and building bulk-mail validation workflows using innocuous “privacy policy update” tracking emails; bypass patterns include “ownership/CTF/bug bounty” pretexts and task decomposition.

References


Emerging Stories

TL;DR

  • [Identity/Authentication] Unit 42 described “Pass-ta-key” attack classes where endpoint malware plus relying-party validation gaps (e.g., weak user-verification enforcement) can enable passkey-protected account takeover in synced passkey ecosystems.
  • [Supply Chain/macOS] Unit 42 reported XCSSET v40’s resurgence: seeding via Xcode projects (incl. open-source), more memory-resident behavior, local worming across Xcode projects, defense impairment, and expanded browser-hijack/trojanizer modules.

References


Forecasts, Detection Opportunities and References...